Inquiry regarding ExpressRoute Circuit connectivity: Coexistence of Standard VNet Gateway and Virtual WAN Hub Gateway

이재옥 145 평판 포인트
2026-04-22T05:52:25.65+00:00

Dear All,

I am currently designing a migration from a traditional Hub-and-Spoke topology to an Azure Virtual WAN (vWAN) architecture. During this transition, a technical debate has arisen regarding the connectivity limits of a single ExpressRoute circuit. I would like to clarify the following scenario:

[Infrastructure Scenario]

Existing Environment: A Hub VNet with a standard ExpressRoute Gateway (Resource Type: Microsoft.Network/virtualNetworkGateways).

New Environment: A Virtual WAN with two Virtual Hubs (vHub 1 & vHub 2) equipped with ExpressRoute Gateways (Resource Type: Microsoft.Network/expressRouteGateways).

Target: A single ExpressRoute Circuit (Standard SKU)

[Core Question]

Is it possible to link a single ExpressRoute circuit to both the standard VNet Gateway and the Virtual WAN Hub Gateways simultaneously?

Specifically, I need to confirm:

Gateway Type Coexistence: Does a single ExpressRoute circuit support concurrent connections to different gateway types (Traditional vs. vWAN)?

Technical Constraints: If not supported, is this due to a limitation in the Private Peering endpoint or a fundamental routing architecture conflict between the two management planes?

Documentation Clarity: While some documentation suggests that an ER circuit can connect to multiple gateways, it is unclear if this "multiple" refers only to gateways of the same type or if it allows a hybrid connection of both standard and vWAN types.

[Our Assumption]

Our current understanding is that an ER circuit must be dedicated to either a traditional gateway environment or a Virtual WAN environment, and cannot bridge both at the same time through a single peering. We believe a "Cut-over" (disconnecting from the old and reconnecting to the new) is required.

Could you please provide an official confirmation or point me to the specific documentation that explicitly defines this coexistence (or lack thereof)?

Thank you for your support.

Best regards,

Azure ExpressRoute
Azure ExpressRoute

온-프레미스 또는 공동 배치 환경에서 Azure 데이터 센터와 인프라 간에 프라이빗 연결을 제공하는 Azure 서비스입니다.


질문 작성자가 수락한 답변
Venkatesan S 10,830 평판 포인트 Microsoft 외부 직원 중재자
2026-04-22T06:35:22.53+00:00

Hi 이재옥,

Thanks for reaching out in Microsoft Q&A forum,

Is it possible to link a single ExpressRoute circuit to both the standard VNet Gateway and the Virtual WAN Hub Gateways simultaneously?

Yes, a single ExpressRoute circuit (Standard SKU) CAN connect simultaneously to both:

  • Your existing traditional ExpressRoute Gateway (Microsoft.Network/virtualNetworkGateways) in the Hub VNet, AND
  • ExpressRoute Gateways (Microsoft.Network/expressRouteGateways) in your Virtual WAN hubs (vHub 1 & vHub 2).

This hybrid coexistence is officially supported and recommended for low-downtime, phased migrations.

Microsoft explicitly documents this scenario in their migration guidance:

"Both the original customer-managed hub virtual network and the new Virtual WAN Hub are both connected to the same ExpressRoute circuit. This allows spokes in both environments to communicate during staged migration." Migrate from hub-spoke topology to Azure Virtual WAN

How It Works:

The key principle is that both gateway types traditional VNet ExpressRoute Gateway and Virtual WAN ExpressRoute Gateway.

Connect through the same private peering on the Microsoft Enterprise Edge (MSEE) devices for a given ExpressRoute circuit.

Core Connectivity Theory:

  1. Single Circuit, Multiple Authorization Keys: Generate separate authorization keys for each gateway-circuit connection. Each gateway redeems its own key independently.
  2. Shared MSEE Peering: Both gateways establish BGP sessions to the identical MSEE private peering endpoint.
  3. Bidirectional Traffic Enablement:
    • Traditional gateway: Enable "Allow traffic from remote Virtual WAN networks"
    • vWAN gateways: Enable "Allow traffic from non-Virtual WAN networks"
    Natural BGP Propagation: Routes from spokes in both environments propagate through the shared circuit, enabling spoke-to-spoke communication across architectures.

Migration Flow:

Phase 1: vWAN hubs deployed with ER gateways
Phase 2: Existing ER circuit connects to vWAN (traditional gateway stays linked)
Phase 3: Hybrid traffic validated (spoke ↔ vWAN spoke via shared circuit)  
Phase 4: Spokes migrate to vWAN progressively
Phase 5: Traditional gateway decommissioned

Architectural Concerns:

No Control Plane Conflicts: Both gateways operate under Microsoft's unified ExpressRoute service fabric. The distinction is in management plane (customer-managed VNet vs. vWAN-managed hubs), not data plane connectivity.

Standard SKU Fully Supported: Circuit SKU limits apply per peering location, not gateway type combinations.

Official Documentation:

Kindly let us know if the above helps or you need further assistance on this issue.

Please do not forget to 210246-screenshot-2021-12-10-121802.pngand “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

이 대답이 도움이 되었나요?

1명이 이 답변이 도움이 된다고 생각했습니다.

0 추가 답변

정렬 기준: 가장 유용함

답변

질문 작성자는 답변을 '승인됨'으로 표시하고, 중재자는 답변을 '추천됨'으로 표시할 수 있습니다. 이를 통해 사용자는 해당 답변이 작성자의 문제를 해결했다는 것을 알 수 있습니다.